Spellbook Review: AI Contract Drafting and Review for Lawyers
Spellbook is one of the more visible entrants in the AI contract drafting space, built as a Microsoft Word add-in that leans on large language models to suggest redlines, generate clauses, flag risks, and answer questions about a draft. It is aimed squarely at transactional lawyers who live inside Word and want an in-line assistant rather than a separate web app. This review looks at what it actually does, where client data goes, how it lines up against recent ethics guidance, and who should — and should not — be buying it.
What Spellbook Actually Does
Spellbook installs as a task pane inside Microsoft Word. Once open, it reads the active document and offers a set of drafting-assistant features: suggested redlines against a chosen party stance, clause generation from a natural-language prompt, benchmarking of terms against what Spellbook has seen in comparable agreements, a review pass that surfaces missing or aggressive provisions, and a chat interface that answers questions grounded in the open document. It also offers a “playbook” feature so a firm or in-house team can encode preferred positions and let the assistant flag deviations. Recent releases have added a broader agentic review mode marketed as Spellbook Associate for multi-step contract review workflows.
Under the hood, Spellbook is powered primarily by OpenAI’s GPT models, a fact the vendor has stated publicly and reiterates in its documentation. That matters for the confidentiality analysis below, because it means the practical data-flow question is not just “what does Spellbook do with my draft” but also “what happens once a subprocessor sees it.”
In day-to-day use, the tool is strongest on first-pass work: generating a plausible clause, spotting obvious omissions in a mid-market commercial agreement, and rewording a paragraph to a different stance. It is weaker — as all current LLM drafting tools are — on anything requiring cross-document memory of a specific matter, jurisdiction-specific niceties, or bespoke deal structures. Treat it as a fast junior with confident prose and no independent judgment.
The Confidentiality Lens
This is the section that matters most, and the one most vendor marketing glosses over. When you invoke a Spellbook feature, the relevant portion of your draft — and in some features, effectively the whole document — leaves your machine, transits Spellbook’s infrastructure, and is sent to an LLM provider (OpenAI, and per Spellbook’s documentation, potentially Anthropic for some features). This is a cloud tool. There is no on-device mode.
Spellbook’s public position, set out in its privacy policy and security page, is that customer content is not used to train Spellbook’s or its subprocessors’ models, that OpenAI has agreed under an enterprise arrangement not to retain content for training, and that data in transit and at rest is encrypted. Spellbook offers a DPA on request and lists SOC 2 Type II compliance. Those are the right table-stakes commitments for a legal-tech vendor in 2025.
What lawyers should still weigh:
- Subpoena surface. A subpoena served on Spellbook could, in principle, reach whatever it stores: account metadata, usage logs, and any prompts or documents retained for abuse-monitoring or short-term operational windows. Confirm current retention windows in your DPA before assuming “zero retention.”
- Subprocessor chain. OpenAI’s zero-retention API arrangement is a contractual commitment, not an architectural one. It is a reason to be reasonably comfortable, not a reason to stop tracking the subprocessor list.
- No BAA. Spellbook is not marketed for PHI workflows. If your matter involves protected health information, this is not the tool.
- Client consent posture. Even with strong vendor controls, sending client drafts to a third-party LLM provider is a disclosure decision. Engagement letters and outside-counsel guidelines increasingly speak to this directly.
None of this is disqualifying — it is the same profile as most cloud legal AI — but it should be a conscious choice, not a default. If your practice includes matters where the mere fact of cloud disclosure is a problem (sensitive investigations, certain government work, opposing-party discovery risk), a local-first tool is a better fit for that slice of work. Basil publishes this review library and builds an on-device notetaker; for drafting specifically, the honest answer is that mature fully-local contract-drafting copilots are still rare, and Spellbook is a reasonable cloud option if the confidentiality math works for you. See Basil for Law for how we think about the on-device tradeoff generally.
Ethics-Opinion Fit (ABA 512)
ABA Formal Opinion 512 (July 2024) is the current baseline for generative AI use by US lawyers, and it maps cleanly onto Model Rule 1.1 (competence), 1.6 (confidentiality), 1.5 (fees), and 5.1/5.3 (supervision). Spellbook fits inside 512, but not automatically:
- Competence. 512 expects lawyers to understand, at a general level, how the tool works and where its outputs can fail. Spellbook’s outputs are LLM-generated prose that can be plausibly wrong. Treat every suggested clause as a draft, not a citation.
- Confidentiality. 512 flags that self-learning tools trained on inputs raise particular concern. Spellbook’s contractual no-training posture with its LLM subprocessors is aligned with that concern, but the opinion still contemplates informed client consent in many scenarios — particularly for highly sensitive matters.
- Supervision. Firms need policies. “The associate ran it through Spellbook” is not a workflow; a policy about when the tool is used, on what matters, and how outputs are checked is.
- Billing. 512 is skeptical of billing AI-accelerated time as if it were unassisted work. If Spellbook cuts a two-hour review to twenty minutes, the bill should reflect that.
The recent NYC Bar Formal Opinion 2025-6 reinforces the confidentiality and supervision themes at the state level. And it is worth remembering the direction of case law: in US v. Heppner (S.D.N.Y. Feb 2026), Judge Rakoff held that a litigant’s chats with a public AI platform were not privileged. Spellbook is not a consumer chatbot, and enterprise LLM arrangements are structurally different, but the underlying instinct — that data handed to a third party invites questions — is one every user of a cloud AI tool should internalize.
Where Spellbook Is Genuinely Good
Credit where it is due. Spellbook’s Word integration is the best part of the product. Lawyers who draft in Word do not want to paste text into a browser tab; having suggestions inline, with track-changes-style acceptance, matches the actual workflow. The playbook feature, when properly configured, is a real force multiplier for teams that review high volumes of a similar contract type (NDAs, MSAs, SaaS order forms). Benchmarking suggestions, while never a substitute for judgment, can prompt useful “did we think about this?” moments. And the product has iterated visibly — the review workflows and agentic features shipped in 2024 and 2025 are meaningfully better than the early clause-suggestion demos.
For solo and small-firm transactional lawyers without access to a well-staffed knowledge-management function, Spellbook approximates something previously available only at larger shops: a searchable, opinionated view of “what does this clause usually look like.”
Where It Falls Short
The gaps are the ones you would expect from a current-generation LLM drafting tool:
- Hallucinated authority. Ask it for a citation and verify it yourself. Every time.
- Jurisdictional blind spots. Suggestions default to a generic US commercial-contract voice. Non-US and specialized-regulatory work will need heavier lawyer overlay.
- Litigation and disputes work. Spellbook is a drafting tool. It is not built for pleadings, discovery, or case strategy.
- Cloud-only. No on-device or self-hosted option, which limits its fit for the most sensitivity-constrained matters.
Pricing and Who It’s For
Spellbook publishes tiered per-seat pricing with a free trial; current numbers are on the Spellbook pricing page. Expect meaningful annual per-seat cost, with higher tiers unlocking playbooks, deeper review features, and admin controls. Enterprise pricing is by quote.
Who it is for:
- Transactional solos and small firms who draft in Word and want first-pass acceleration.
- In-house legal teams handling recurring contract types where a playbook pays for itself.
- Mid-market firms piloting AI drafting with a defined policy and a DPA in place.
Who should look elsewhere:
- Litigators — wrong tool category.
- Practices handling PHI or other data requiring a BAA.
- Lawyers whose matters cannot tolerate any cloud disclosure, contractual no-training assurances notwithstanding.
Verdict
Spellbook is a competent, Word-native contract drafting copilot that has matured well past its initial clause-suggestion demo. It is not magic, and it is not a substitute for lawyer judgment, but for transactional work in a firm that has done its ethics and confidentiality homework, it can meaningfully compress first-pass drafting and review. The confidentiality profile is standard cloud-LLM: acceptable for most transactional matters if you have a DPA and a policy, unsuitable for the most sensitive slice.
| Pros | Cons |
|---|---|
| Native Word integration matches real drafting workflow | Cloud-only; sends drafts to third-party LLM providers |
| Playbooks meaningfully speed up repeat contract types | Outputs can be confidently wrong; requires lawyer review |
| Contractual no-training posture with LLM subprocessors | No BAA; not suitable for PHI workflows |
| Active product development and clear enterprise controls | Weak on non-US jurisdictions and specialized regulatory work |
| Reasonable fit with ABA Opinion 512 when paired with firm policy | Per-seat pricing adds up quickly for larger teams |
This review is for information only and is not legal advice.
Frequently asked questions
Does Spellbook train its AI on my contracts?
Per Spellbook's published privacy policy and security documentation, customer content is not used to train Spellbook's models, and its LLM subprocessors (notably OpenAI) operate under enterprise arrangements that contractually preclude use of API content for training. Confirm the current terms in your own DPA before relying on this, as subprocessor arrangements can change.
Can I use Spellbook and stay within ABA Formal Opinion 512?
Yes, in principle, but Opinion 512 requires competence, confidentiality analysis, supervision, and honest billing. That means understanding at a general level how the tool works, having a firm policy on when it is used, verifying outputs, considering client consent for sensitive matters, and not billing AI-accelerated work as if it were unassisted.
Is Spellbook appropriate for litigation work?
No. Spellbook is a transactional drafting and review tool built as a Word add-in. It is not designed for pleadings, discovery review, case analysis, or litigation strategy, and using it for those purposes would be off-label.
What could a subpoena served on Spellbook actually reach?
In principle, a subpoena could reach whatever Spellbook stores: account and billing metadata, usage logs, and any prompts or documents retained during operational or abuse-monitoring windows. The precise scope depends on current retention settings in your DPA and on subprocessor arrangements, so review those directly rather than relying on marketing summaries.
Does Spellbook offer a BAA for healthcare-related work?
Spellbook is not marketed as a HIPAA-compliant tool and does not generally offer a BAA. If your matter involves protected health information, you should use a tool specifically designed and contracted for that use case.
How does Spellbook compare to using ChatGPT directly for contract drafting?
Spellbook is built on LLMs including OpenAI's models but adds a Word-native interface, contract-specific workflows, playbooks, and enterprise contractual protections around data handling. Using a consumer AI chatbot directly for client contracts raises significantly greater confidentiality and, as illustrated by US v. Heppner (S.D.N.Y. 2026) in a different context, potentially privilege concerns.
Meeting notes with no server to subpoena
Basil transcribes and summarizes entirely on-device — privilege-safe by architecture. See Basil for Law →
This review is for information only and is not legal advice.